NetBird VPN does not remove the default password of an admin account
Critical severity
GitHub Reviewed
Published
Oct 20, 2025
to the GitHub Advisory Database
•
Updated Oct 20, 2025
Package
Affected versions
< 0.57.0
Patched versions
0.57.0
Description
Published by the National Vulnerability Database
Oct 20, 2025
Published to the GitHub Advisory Database
Oct 20, 2025
Reviewed
Oct 20, 2025
Last updated
Oct 20, 2025
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL.
This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.
This issue has been fixed in version 0.57.0.
References